UK U.K. orders Apple to let it spy on users’ encrypted accounts - Secret order requires blanket access to protected cloud backups around the world, which if implemented would undermine Apple’s privacy pledge to its users.

By Joseph Menn
February 7, 2025 at 2:30 a.m. EST

1738943791282.png
(Illustration by Laura Padilla Castellanos/The Washington Post; iStock)

Security officials in the United Kingdom have demanded that Apple create a back door allowing them to retrieve all the content any Apple user worldwide has uploaded to the cloud, people familiar with the matter told The Washington Post.

The British government’s undisclosed order, issued last month, requires blanket capability to view fully encrypted material, not merely assistance in cracking a specific account, and has no known precedent in major democracies. Its application would mark a significant defeat for tech companies in their decades-long battle to avoid being wielded as government tools against their users, the people said, speaking under the condition of anonymity to discuss legally and politically sensitive issues.

Rather than break the security promises it made to its users everywhere, Apple is likely to stop offering encrypted storage in the U.K., the people said. Yet that concession would not fulfill the U.K. demand for backdoor access to the service in other countries, including the United States.

The office of the Home Secretary has served Apple with a document called a technical capability notice, ordering it to provide access under the sweeping U.K. Investigatory Powers Act of 2016, which authorizes law enforcement to compel assistance from companies when needed to collect evidence, the people said.

The law, known by critics as the Snoopers’ Charter, makes it a criminal offense to reveal that the government has even made such a demand. An Apple spokesman declined to comment.

Apple can appeal the U.K. capability notice to a secret technical panel, which would consider arguments about the expense of the requirement, and to a judge who would weigh whether the request was in proportion to the government’s needs. But the law does not permit Apple to delay complying during an appeal.

In March, when the company was on notice that such a requirement might be coming, it told Parliament: “There is no reason why the U.K. [government] should have the authority to decide for citizens of the world whether they can avail themselves of the proven security benefits that flow from end-to-end encryption.”

The Home Office said Thursday that its policy was not to discuss any technical demands. “We do not comment on operational matters, including for example confirming or denying the existence of any such notices,” a spokesman said.

Senior national security officials in the Biden administration had been tracking the matter since the United Kingdom first told the company it might demand access and Apple said it would refuse. It could not be determined whether they raised objections to Britain. Trump White House and intelligence officials declined to comment.

One of the people briefed on the situation, a consultant advising the United States on encryption matters, said Apple would be barred from warning its users that its most advanced encryption no longer provided full security. The person deemed it shocking that the U.K. government was demanding Apple’s help to spy on non-British users without their governments’ knowledge. A former White House security adviser confirmed the existence of the British order.

At issue is cloud storage that only the user, not Apple, can unlock. Apple started rolling out the option, which it calls Advanced Data Protection, in 2022. It had sought to offer it several years earlier but backed off after objections from the FBI during the first term of President Donald Trump, who pilloried the company for not aiding in the arrest of “killers, drug dealers and other violent criminal elements.” The service is an available security option for Apple users in the United States and elsewhere.

While most iPhone and Mac computer users do not go through the steps to enable it, the service offers enhanced protection from hacking and shuts down a routine method law enforcement uses to access photos, messages and other material. iCloud storage and backups are favored targets for U.S. search warrants, which can be served on Apple without the user knowing.

Law enforcement authorities around the world have complained about increased use of encryption in communication modes beyond simple phone traffic, which in the United States can be monitored with a court’s permission.

The U.K. and FBI in particular have said that encryption lets terrorists and child abusers hide more easily. Tech companies have pushed back, stressing a right to privacy in personal communication and arguing that back doors for law enforcement are often exploited by criminals and can be abused by authoritarian regimes.

Most electronic communication is encrypted to some degree as it passes through privately owned systems before reaching its destination. Usually such intermediaries as email providers and internet access companies can obtain the plain text if police ask.

But an increasing number of tech offerings are encrypted end to end, meaning that no intermediary has access to the digital keys that would unlock the content. That includes Signal messages, Meta’s WhatsApp and Messenger texts, and Apple’s iMessages and FaceTime calls. Often such content loses its end-to-end protection when it is backed up for storage in the cloud. That does not happen with Apple’s Advanced Data Protection option.

Apple has made privacy a selling point for its phones for years, a stance that was enhanced in 2016 when it successfully fought a U.S. order to unlock the iPhone of a dead terrorist in San Bernardino, California. It has since sought to compromise, such as by developing a plan to scan user devices for illegal material. That initiative was shelved after heated criticism by privacy advocates and security experts, who said it would turn the technology against customers in unpredictable ways.

Google would be a bigger target for U.K. officials, because it has made the backups for Android phones encrypted by default since 2018. Google spokesman Ed Fernandez declined to say whether any government had sought a back door, but implied none have been implemented. “Google can’t access Android end-to-end encrypted backup data, even with a legal order,” he said.

Meta also offers encrypted backups for WhatsApp. A spokesperson declined to comment on government requests but pointed to a transparency statement on its website saying that no back doors or weakened architecture would be implemented.

If the U.K. secures access to the encrypted data, other countries that have allowed the encrypted storage, such as China, might be prompted to demand equal backdoor access, potentially prompting Apple to withdraw the service rather than comply.

The battle over storage privacy escalating in Britain is not entirely unexpected. In 2022 U.K. officials condemned Apple’s plans to introduce strong encryption for storage. “End-to-end encryption cannot be allowed to hamper efforts to catch perpetrators of the most serious crimes,” a government spokesperson told the Guardian newspaper, referring specifically to child safety laws.

After the Home Office gave Apple a draft of what would become the backdoor order, the company hinted to lawmakers and the public what might lie ahead.

During a debate in Parliament over amendments to the Investigatory Powers Act, Apple warned in March that the law allowed the government to demand back doors that could apply around the world. “These provisions could be used to force a company like Apple, that would never build a back door into its products, to publicly withdraw critical security features from the UK market, depriving UK users of these protections,” it said in a written submission.

Apple argued then that wielding the act against strong encryption would conflict with a ruling by the European Court of Human Rights that any law requiring companies to produce end-to-end encrypted communications “risks amounting to a requirement that providers of such services weaken the encryption mechanism for all users” and violates the European right to privacy.

In the United States, decades of complaints from law enforcement about encryption have recently been sidelined by massive hacks by suspected Chinese government agents, who breached the biggest communications companies and listened in on calls at will. In a joint December press briefing on the case with FBI leaders, a Department of Homeland Security official urged Americans not to rely on standard phone service for privacy and to use encrypted services when possible.

Also that month, the FBI, National Security Agency and the Cybersecurity and Infrastructure Security Agency joined in recommending dozens of steps to counter the Chinese hacking spree, including “Ensure that traffic is end-to-end encrypted to the maximum extent possible.”

Officials in Canada, New Zealand and Australia endorsed the recommendations. Those in the United Kingdom did not.

Source (Archive)
 
So this is essentially a secret order from a secret panel, telling Apple to put in a secret backdoor so they can snoop into peoples secrets...

Think we might need to redefine the meaning of the word "secret".....
The British government has a very, very odd view of that word. They once declared a fuck-huge tower in the middle of London with a publicly-accessible restaurant at the top covered under the Official Secrets Act due to the fact it had a ton of highly visible radio antennas all over it for telecommunications purposes.
 
Since when have they been concerned about pedophiles and rapists? They don't need Apple to find those, they literally have them roaming the streets with zero consequences.
 
UK Government Secretly Orders Apple to Build Global iCloud Backdoor, Threatening Digital Privacy Worldwide
Reclaim The Net (archive.ph)
By Christina Maas
2025-02-07 18:35:44GMT
Imagine waking up one morning to find out your government has demanded the master key to every digital iPhone lock on Earth — without telling anyone. That’s exactly what British security officials have tried to pull off, secretly ordering Apple to build a backdoor into iCloud that would allow them to decrypt any user’s data, anywhere in the world. Yes, not just suspected criminals, not just UK citizens — everyone. And they don’t even want Apple to talk about it.

This breathtakingly authoritarian stunt, first reported by The Washington Post, is one of the most aggressive attempts to dismantle digital privacy ever attempted by a so-called Western democracy. It’s the kind of thing you’d expect from regimes that plaster their leader’s face on every street corner, not from a country that still pretends to believe in civil liberties.

The Order: Total Access, Zero Oversight
This isn’t about catching a single terrorist or cracking a single case. No, this order — issued in secret last month by Keir Starmer’s Labour government — demands universal decryption capabilities, effectively turning Apple into a surveillance arm of the UK government. Forget warrants, forget oversight, forget even the pretense of targeted investigations. If this order were obeyed, British authorities would have the power to rifle through anyone’s iCloud account at will, no justification required.

The officials pushing for this monstrosity are hiding behind the UK’s Investigatory Powers Act of 2016, a law so Orwellian it’s lovingly referred to as the “Snoopers’ Charter.” This piece of legislative overreach forces tech companies to comply with government spying requests while making it illegal to even disclose that such demands have been made. It’s the surveillance state’s dream—limitless power, zero accountability.

Apple’s Answer: Thanks, But No Thanks
Apple, to its credit, has not rolled over — yet. Instead of turning itself into an informant for MI5, the company is reportedly considering pulling encrypted iCloud storage from the UK entirely. In other words, British users could lose a major security feature because their government is hell-bent on playing digital dictator.

But even that isn’t enough for UK authorities, who aren’t just demanding access to British accounts. They want a skeleton key to iCloud data worldwide, including in the US That’s right—British intelligence, in a stunning display of overreach, is trying to force an American company to compromise American users on American soil.

The “Appeal” Process: A Kafkaesque Farce
Technically, Apple has the right to challenge this order. But in true dystopian fashion, its only option is to plead its case before a secret technical panel, which will then determine if the request is too expensive. If that doesn’t work, Apple can go before a judge, who will decide whether the demand is “proportionate” to the government’s needs. Because if there’s one thing we know about government surveillance, it’s that it’s always reasonable and restrained.

Meanwhile, Apple has refused to comment, likely because doing so would be a criminal offense under UK law. That’s right — even talking about the demand could land Apple executives in legal trouble. Nothing screams “free society” like threatening jail time for discussing government overreach.

Here’s the wider issue: even if Apple were to challenge this draconian demand, it wouldn’t matter. The law requires immediate compliance — meaning that even as Apple fights the order, it would still be forced to hand over the keys in the meantime. It’s the legal equivalent of being forced to serve a prison sentence while appealing your conviction. By the time the courts make a decision, the damage is already done.

Apple, to its credit, saw this Orwellian nightmare coming from a mile away. Last year, it explicitly warned British lawmakers that such a demand would be nothing less than an assault on global privacy. The company made its stance clear:

“There is no reason why the U.K. [government] should have the authority to decide for citizens of the world whether they can avail themselves of the proven security benefits that flow from end-to-end encryption.”

In other words: Who the hell does Britain think it is? The UK government, in its wisdom, apparently believes it should have the power to determine how encryption works for everyone, everywhere, not just in its own backyard. Because why stop at surveillance when you can have global surveillance?

The Official Non-Denial Denial
Of course, when asked about this breathtakingly bold power grab, the UK Home Office fell back on the bureaucrat’s favorite escape hatch: refusing to confirm or deny reality itself.

“We do not comment on operational matters, including for example confirming or denying the existence of any such notices.”

In other words, “We won’t admit we’re demanding this, but we won’t deny it either.” Because why be transparent when you can keep the public guessing?

How the UK Plans to Kill Encryption by Exploiting the Cloud
For those still clinging to the idea that end-to-end encryption will protect their messages from prying eyes, here’s the bad news: the UK government already has a backdoor, and most people don’t even realize it.

Yes, apps like iMessage, WhatsApp, and Signal use end-to-end encryption, meaning only the sender and recipient can read the messages. But the moment you back up those encrypted chats to the cloud? They become fair game. Law enforcement can demand access through legal orders, bypassing encryption entirely.

Apple’s Advanced Data Protection was designed to close this loophole, giving users a way to keep their cloud backups as secure as their messages. And that, of course, is precisely why the UK wants to kill it.

Because for governments that dream of unlimited surveillance, letting people secure their own data is simply unacceptable.

The UK Is Now Outpacing the US in Anti-Privacy Extremism
For years, the US has led the charge in trying to undermine encryption, with the FBI repeatedly demanding backdoors and government officials throwing tantrums whenever a tech company refuses to play ball. But even America has never gone this far.

Now, Britain is attempting to leap ahead, pushing for surveillance powers that would force not just UK companies, but global tech giants to comply — regardless of where their users live. And Apple? It’s just the first target.

Google, which has offered default encrypted backups for Android since 2018, could easily be next. When asked whether the UK or any other government had made similar demands, Google spokesperson Ed Fernandez gave a carefully worded response:

“Google can’t access Android end-to-end encrypted backup data, even with a legal order.”

That’s a fancy way of saying “We don’t have the keys, and we’re not planning to give them up.” But how long until the UK demands that Google build a key, just like it’s demanding from Apple?

And then there’s Meta. WhatsApp’s encrypted backups are another thorn in the side of surveillance-hungry governments. When pressed on whether they had received any secret orders for access, Meta, predictably, refused to comment.
 
Honestly, compared to what it would do to their business, Apple would likely just take its ball and go home rather than acquiesce to the UK's demands. I don't think the UK government understands how close they literally are to shooting their own foot and blowing the damn thing right off in the process.
 
Honestly, compared to what it would do to their business, Apple would likely just take its ball and go home rather than acquiesce to the UK's demands. I don't think the UK government understands how close they literally are to shooting their own foot and blowing the damn thing right off in the process.
I think there are a lot of demands right now from the Controllers that white countries that are not the US accelerate, to try to cause as much damage and get as many critical path items closed as possible lest their citizens get inspired to remember who they are, too.
 
Apple caved and went along with the request. New users in the UK no longer have end-to-end encryption on Apple devices, and existing ones are going to lose it.

From Tuta, an encrypted email outfit:

It's been only ten days since we warned that the UK government could force Apple to undermine encryption. Now the Silicon Valley Big Tech complied, partially. Apple removed the end-to-end encryption feature of their cloud feature for new users in the UK. This is a serious warning to everyone concerned about privacy: It's the first time one of the Five Eyes successfully pressured a company to remove their encryption for being able to pass on data to the authorities if requested. Given the increasing cyberthreats, this unprecedented move by Apple is shocking.

What is even more shocking is that Apple’s move could not go far enough: The request issued to Apple under the Investigatory Powers Act demands that Apple enables access to cloud data of all their global users. The current change only affects new users from the UK. Existing users in the UK will get a warning at some point that they need to disable end-to-end encryption, or they will lose access to their accounts. As Apple does not have a backdoor key, the user needs to disable the end-to-end encryption themselves.

So while Apple continues to frame this in a way that it is not a backdoor, UK users must feel awfully cheated. Their data in the Apple cloud can no longer be encrypted end-to-end, leaving it at an increased risk for data breaches, malicious attacks, and governmental access.

While Apple successfully fought a similar request by the US government ten years ago, they now gave in to political pressure setting an awful precedent. End-to-end encryption is the only tool we have that can protect our data. We all know that a backdoor for the good guys only is not possible.
 
Just pull out of the UK. You‘re too big to be bullied by them, so just pull out. “Oh but you’re protecting pedophiles and terrorists!” No fuck you, tired of this bullshit plea being made to allow further incursion into everyone’s lives. You have plenty of tools already to find and catch retards, but you‘re incentivized against it. You won’t use it to catch them you’ll use it to catch wrong thinkers.
Also, the cry of "you're defending pedos and terrorists" means nothing when the British defend Islamic terrorists and venerate their pedo antics.
 
I guess greed trumped that ethos and they just couldn't risk losing the UK market.
Not exactly. I'll be that guy and quote myself from another thread.

First, the law is very clear on this issue. The state has arrogated to itself the right to demand these back doors be put in place, with a clear schedule of very large fines as punishment for non-compliance.

Second, Apple cannot comply with the demand; it is physically impossible.

Third, the UK is no longer a significant market for Apple.

Apple don't want to spend years in a protracted battle with the UK government over something that they cannot resolve. British courts do not have the same power to overturn law as American courts and are unlikely to grant any sort of injunctive relief in the matter, so Apple will be facing huge fines, which will become significantly greater than the revenue they take from UK customers in short order. It's cheaper for them to withdraw the app entirely.
 
So what happens if say, I buy a phone abroad in Europe and it’s registered in Europe. But I use it in the uk? Is everyone who passes through here on business going to lose privacy? They do understand that any real bad people will just purchase a phone elsewhere and use a VPN?
Also do we know on what date it will be removed from uk registered people who already set it up?
 
Could you kindly expand on the second point? It has piqued my interest.
One of Apple's big autismo obsessions is user security, which led them to create ever more secure means of encrypting and protecting user data on their devices and services. They implemented an end-to-end encryuption service for cloud storage, where data is encrypted on the user's device before it is uploaded to their storage system. The government demanded a "back door" into that service. There's no way for Apple to implement such a back door, because the information is encrypted before it reaches Apple's systems, and Apple doesn't have access to the keys used to encrypt the data. Those keys are generated on the user's device, based on a varieety of things they keep secret, and held in an otherwise inaccessible security container, so only the user's device can decrypt the data again. Apple therefor can't decrypt any of the data to comply with any government demands.

The whole system is designed this way in order to qualify for a National Cyber Security Centre certification (and the certifications of other equivalent national bodies), which qualifies Apple's devices for use by the government and state employees. Apparently, nobody bothered to check whether this law would contradict established legal and regualtory requirements for device encryption.
 
So what happens if say, I buy a phone abroad in Europe and it’s registered in Europe. But I use it in the uk? Is everyone who passes through here on business going to lose privacy? They do understand that any real bad people will just purchase a phone elsewhere and use a VPN?
Also do we know on what date it will be removed from uk registered people who already set it up?
Here's a better thought: what's stopping the US from asking the UK to spy on American Apple phones? I know there's no way in hell that the phone Britain gets will be any different than a phone America gets.
The whole system is designed this way in order to qualify for a National Cyber Security Centre certification (and the certifications of other equivalent national bodies), which qualifies Apple's devices for use by the government and state employees. Apparently, nobody bothered to check whether this law would contradict established legal and regualtory requirements for device encryption.
Either government workers will be getting stronger phones or there will no longer be any phones that can be used by the fedboys.
 
The British government has a very, very odd view of that word. They once declared a fuck-huge tower in the middle of London with a publicly-accessible restaurant at the top covered under the Official Secrets Act due to the fact it had a ton of highly visible radio antennas all over it for telecommunications purposes.
Have you ever watched Clarkson's farm? It's show very well how insane the government is over there, especially season 2. I don't understand how they haven't had multiple Marvin Heemeyers over there.
 
Have you ever watched Clarkson's farm? It's show very well how insane the government is over there, especially season 2. I don't understand how they haven't had multiple Marvin Heemeyers over there.
No, but I have seen Yes, Minister and the thread here in A&N is pretty solid.
 
One of Apple's big autismo obsessions is user security, which led them to create ever more secure means of encrypting and protecting user data on their devices and services. They implemented an end-to-end encryuption service for cloud storage, where data is encrypted on the user's device before it is uploaded to their storage system. The government demanded a "back door" into that service. There's no way for Apple to implement such a back door, because the information is encrypted before it reaches Apple's systems, and Apple doesn't have access to the keys used to encrypt the data. Those keys are generated on the user's device, based on a varieety of things they keep secret, and held in an otherwise inaccessible security container, so only the user's device can decrypt the data again. Apple therefor can't decrypt any of the data to comply with any government demands.

The whole system is designed this way in order to qualify for a National Cyber Security Centre certification (and the certifications of other equivalent national bodies), which qualifies Apple's devices for use by the government and state employees. Apparently, nobody bothered to check whether this law would contradict established legal and regualtory requirements for device encryption.
Thank you for the information. Your analysis is always appreciated.

To me, if what I understand is correct, then Apple have either said; Yes - and complied with the demand while doing nothing, or Yes - and complied with the command knowing security (in general) has more holes than swiss cheese and more backdoors than a crafty butcher's convention.
 
Thank you for the information. Your analysis is always appreciated.

To me, if what I understand is correct, then Apple have either said; Yes - and complied with the demand while doing nothing, or Yes - and complied with the command knowing security (in general) has more holes than swiss cheese and more backdoors than a crafty butcher's convention.
Basically they said "we can't give you this, so we're not allowing anyone in the country to have it." While yes this is sucky for UK users, at the very least it is an open "fuck you" and doesn't create any secret backdoor.

If they complied and then never gave the backdoor demanded, they would've been open to fines and such.
 
Atrás
Top Abajo